ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Two-factor authentication 'not the solution' to online fraud

Published: 16 Mar 2005 08:45 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Plans to bolster online security with code-generating doodads, fingerprint readers or smart cards are not likely to solve the identity fraud problems currently plaguing database companies and online stores, a security expert has warned.

Two-factor authentication, or the use of a method in addition to a password to verify identity, could still be defeated by Trojan horses and phishing attacks, Bruce Schneier, a renowned cryptographer and the chief technology officer for network protection company Counterpane Internet Security, said on Tuesday.

"Since we have proposed the solution, the problems have changed," Schneier said in an interview with ZDNet UK sister site CNET News.com. "People are selling two-factor authentication as the solution to our current identity-theft problems, but it was designed to solve the issues from 10 years ago."

The well-known encryption expert, who has authored books on information security and terrorism, argued in a posting to his blog that e-commerce companies and security providers need to think more deeply about what two-factor authentication can solve.

"It's not going to prevent identity theft," he wrote. "It's not going to secure online accounts from fraudulent transactions."

Schneier's no-confidence vote comes a day after Microsoft renewed calls at the CeBIT conference in Hannover, Germany, to supplement passwords with another identity check. It also comes on the same day that the US Congress held a hearing on several high-profile data leaks that occurred in the past month.

A representative of Microsoft was not immediately available for comment, but the company confirmed that it did argue for further security checks at the German conference.

While his arguments seem to run counter to Microsoft's effort, Schneier stressed that the software maker's focus on improving security beyond passwords, for example with the use of key fob-size hardware tokens, is a good one.

"Doing away with passwords is a good idea," he said. "Tokens work great, with employees logging onto the corporate server."

However, what's good in a closed corporate network is not as useful on the "anything goes" Internet, Schneier said. Trojan horses can be created that let the attacker know when someone is logged into their bank account and, even with a second identity check, could insert new transactions into the session. Also, online thieves could take control of a server that routes Internet traffic and then develop programs to similarly insert fraudulent transaction into a banking session.

"The tactics will change," Schneier said.

That may be true, but that does not mean that enhancing security with a fingerprint-reading or code-generating device is a bad thing, said Chris Voice, chief technology officer at security company Entrust. Raising the bar for attackers will give some respite from attacks and make fraud that much harder to do, he said.

"You don't stand still just because the criminals are going to evolve," he said. "You still put the lock on the door."

Yet online service providers should look to more permanent solutions, Schneier said. While two-factor authentication does not solve the problem, security companies should still re-analyse the issues, he said.

"Focus on the problem: Fraudulent transactions," he said. "There are two strategies: You can make identities harder to steal, or you can make identities less useful. I think the first fails in the end."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
104 out of 194 people found this useful



Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

SAP Retail Solutions Project Manager / Integration Architect

All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, ...

Test Consultant

All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, ...

Network Engineer - Aberdeen - Up to 50,000

Extensive experience with session border controllers, NAT/Firewall traversal, gatekeepers and call accounting techniques Excellent technical and ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment